01adc841fa
Adjudicated and verified by me, not taken from the PR body.
What I measured on the merged revision (099b2ecf… for the worker's own
commit, b5843ab for the head I merged):
* 5 test functions defined, 5 invoked; suite exit 0, "PASS: probe member
credentials guards"
* bash -n rc=0 on both scripts under /bin/bash 3.2.57 and bash 5.3.9
* two mutations killed, each proven applied two ways (mutant present AND
original gone), restored byte-identical, with a green control after each:
- dropping the empty-parse special case -> FAIL: empty parser output
count: missing policy parser (jq) returned 0 field(s)
- arity threshold 5 -> 0 -> FAIL: short parser output status
The PR's own mutation proofs were run against revision 0e243e03, before
its final edit, so I re-ran them against what I actually merged.
Two things I fixed at the gate rather than sending back:
* The refactor stranded about 25 lines of explanatory comments at the old
parse site — including "Check the count here" pointing at a function
call instead of the check, and a pipefail note saying "handled below"
about code now above it. That is the same wrong-stated-fact defect class
as fleetd #500, in the very file whose ticket history is about it. Moved
each block above the code it explains.
* Two assertions matched on `jq) returned N field(s)`, a needle starting
mid-parenthetical, so a real failure printed "missing jq) returned 0
field(s)" and read as if the script's message had an unbalanced paren.
Widened to `policy parser (jq) returned N field(s)`, which also pins
that the refusal names the parser it used.
Caveats recorded, from the implementer and not re-checked by me: the
harness does not cover the non-member, missing-parser, curl-fetch,
known-count, or hash-tool fallback paths.
One property worth noting in favour of this suite: it runs under `set -e`,
so the first failing test aborts before the final `printf 'PASS: …'`. That
PASS line is reachable only from the fully successful path.